科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ Entropy (Basel, Switzerland)2026-09-15

Detecting Unseen IoT Attacks with Calibrated Dual Evidence Under Low False-Positive Budget.

Jiahui Yue, Yuliang Lu, Yi Xie

原始摘要(英文原文)· Original abstract
Internet of Things (IoT) traffic anomaly detection is essential for limiting device compromise and large-scale attacks. Existing detectors may miss attack families absent from model development, while heterogeneous benign traffic makes it difficult to maintain a low false-positive rate (FPR). To address these two practical limitations, we propose the Mode-Calibrated Dual-Evidence Detector (MCDE). Its supervised branch estimates the probability that a sample is malicious from labeled benign and known-attack traffic, while its benign-deviation branch measures distance from multiple learned benign traffic modes, providing a complementary route for unseen attacks. MCDE maps the heterogeneous probability and distance scores to comparable empirical benign-tail evidence, normalizes each branch by its allocated share of the target FPR, and fuses them into an anomaly score. A disjoint held-out benign set determines the decision threshold. Equivalently, the fusion compares budget-adjusted benign-tail surprisal, linking the decision rule to empirical self-information. We further establish the conditions under which the budgeted fusion controls the nominal overall FPR. Family-hold-out experiments on IoT-23 and N-BaIoT validate MCDE. At a 1% target benign FPR, MCDE improves IoT-23 unseen recall over histogram-based gradient boosting from 85.77% to 90.85% and harmonic known-unseen recall from 91.82% to 95.07%, while maintaining a 0.96% benign-test FPR. It also achieves 99.87% unseen recall on N-BaIoT.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Detecting Unseen IoT Attacks with Calibrated Dual Evidence Under Low False-Positive Budget. — 科研速览 Science Skim